Mutual Authentication Protocol for HTTP
RFC 8120, “Mutual Authentication Protocol for HTTP”, is an Experimental document published in April 2017 by Y. Oiwa, H. Watanabe, H. Takagi, K. Maeda, T. Hayashi, Y. Ioku. The canonical text is published by the RFC Editor.
Abstract
This document specifies an authentication scheme for the Hypertext Transfer Protocol (HTTP) that is referred to as either the Mutual authentication scheme or the Mutual authentication protocol. This scheme provides true mutual authentication between an HTTP client and an HTTP server using password-based authentication. Unlike the Basic and Digest authentication schemes, the Mutual authentication scheme specified in this document assures the user that the server truly knows the user's encrypted password.
What “Experimental” means
Describes a specification that is part of a research or development effort, published so the community can gain experience with it.
The canonical text of RFC 8120 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 8119 SIP "cause" URI Parameter for Service Number Translation
- RFC 8121 Mutual Authentication Protocol for HTTP: Cryptographic Algorithms Based on the Key Agreement Mechanism 3
- RFC 8118 The application/pdf Media Type
- RFC 8122 Connection-Oriented Media Transport over the Transport Layer Security Protocol in the Session Description Protocol
- RFC 8117 Current Hostname Practice Considered Harmful
- RFC 8123 Requirements for Marking SIP Messages to be Logged
- RFC 8116 Security Threats to the Optimized Link State Routing Protocol Version 2
- RFC 8124 The Session Description Protocol WebSocket Connection URI Attribute